Repository navigation
feat: seamless add, for an existing Express, Fastify or React project - #255
Merged
Merged
Conversation
Detects the backend and web app, connects a local auth server (written to seamless/, secrets gitignored) or a managed application, writes the backend's .env and the web app's API URL without touching existing values or comments, installs the adapter and SDK with the project's package manager, and prints the code to add in TypeScript or JavaScript. It never edits source files. To share the managed connection with init, resolveJwksKid, issueServiceToken, requireInstanceUrl and connectable move into core/managedConnect. runCommand uses a shell only on Windows, where npm is a .cmd script; elsewhere arguments reach the program as given, so a path with spaces is not re-split and Node 24 no longer warns (DEP0190). Refs #210
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #210. Part of fells-code/seamless-auth-api#371. Depends on #254, which pins the auth server at v0.18.0.
seamless addadds Seamless Auth to a project you already have.seamless initonly starts new ones.It never edits the project's source files. It:
api/,server/,backend/,web/,client/,frontend/,apps/*andpackages/*, and records each one's language, entry file and package manager (npm, pnpm, yarn or bun, read from the nearest lock file up to the repo root). Go, Rust, Python, Angular, Vue, Svelte and Next.js are reported as not wired yet (feat(add): add Seamless Auth to existing Go, Rust, Python, Angular, Vue and Svelte projects #248).initdoes.--localwritesseamless/docker-compose.yml(the auth server on127.0.0.1:5312, and Postgres with no published port, because the project may already run its own) andseamless/.env, which holds the secrets and is gitignored.APP_ORIGINSandORIGINScome from the project's real origins.--appconnects a managed application withinit's own helpers, now incore/managedConnect.ts. Under--yesyou must pass--localor--app, and replacing a stack or rotating a token needs--force, as ininit..envgets the auth server URL and issuer, service token and key id, and keeps the existing cookie secret,UI_ORIGINSand every other line or comment. A new merge writer (core/envFile.ts) does this, becausewriteEnvrewrites the whole file. The web app's.env.localgets its API URL.addwarns if the backend.envis not gitignored.cookie-parserandcorsfor Express,@fastify/corsfor Fastify) and@seamless-auth/reactwith the project's package manager.--skip-installprints the commands instead./auth, credentialed CORS for the web origin, a protected/api/me, the/consolemount when enabled, development-only logging of one-time codes (the auth server does not send them in development), and thereq.usertyping for TypeScript Express.Verified end to end
I built a fresh Express 5 + TypeScript API and a stock Vite
react-tsapp (npm create vite), then ranseamless add --local. I pasted the printed code in as a user would. Both halves pass their owntsc. I started the stack (auth image at v0.18.0, as #254 sets it) and drove the backend over HTTP:/route still answers/consoleserves the dashboard/api/me, bearer sign-in, and logoutI then did the same for a plain JavaScript Fastify app (
--admin=none), and checked that its printed code passesnode --check.The first run caught three bugs, all fixed here:
req.userdid not typecheck in a TypeScript Express app..envinto an app that does not already.runCommandtriggered Node 24's DEP0190 warning.Other changes
runCommanduses a shell only on Windows. Every caller passes plain argument arrays, so this is safe, and it stops paths with spaces being re-split.resolveOwnerEmailis exported soaddasks for the owner asinitdoes.Tests: 1222 pass, plus 45 new ones (
detect,envFile,authStack,snippets, andaddfor local, managed, interactive and edge cases).tsc --noEmitandbuildpass, and coverage is above the thresholds.